CVE-2012-1823
Not scored
Confirmed as exploited
PHP-CGI Query String Parameter Vulnerability
sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.
Exploit probability
100.0%
Published
Not available
Required by
April 15, 2022
Last source change
Not available
01 / ACTION
Required action
Apply updates per vendor instructions.
04 / EVIDENCE
Source records
Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities
CVE-2012-1823
View original source
sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.